Privacy & Trust

Built to show you patterns — not to spy on you.

FocusMirror is an attention mirror: it reflects how your day actually went so you can act on it. A tool that watches how you work has to earn the right to — so below is every commitment we make, each mapped to the code that enforces it, not a policy promise.

The plain-English version

FocusMirror sees which apps and sites you use — never what you type or read in them. Window titles never leave your device. You choose what's invisible, and that filtering happens on your device before anything uploads. Your data is never sold or shared, and it belongs to you alone: no employer, no team admin, no boss dashboard. Delete it all whenever you want, and it's actually gone.

What we collect — during sessions only

  • App namee.g. “Cursor”
  • App bundle ide.g. com.todesktop…
  • Site domainnever full URLs
  • Time rangesstart and end of each stretch
  • Session goalif you type one
  • Category labelscatalog or AI-assigned
  • Your account emailfor sign-in

What we never collect

  • Keystrokes or anything you type
  • Screenshots or screen contents
  • Window titles — read on your device to apply your exclusion rules, then discarded. The upload is rejected by schema if a title sneaks in, and the database has no column to store one.
  • Full URLs or search queries
  • Page, document, or message content
  • Anything from excluded apps or domains
  • Anything while paused or stopped
Inspect the boundary

Click anything. See exactly how far it travels.

Not a promise — a boundary. Pick something FocusMirror runs into and see whether it leaves your device, gets stored, or could ever reach an employer.

Where it goes
Leaves your deviceYes
Stored on our serverYes
Used to write summariesYes
Shown back to youYes
Visible to an employerNo

The domain and the time range are the metadata FocusMirror reflects back. The full URL and page content never leave your Mac.

Where your data goes

Three steps. It gets less, not more, sensitive.

Step 1 · Your device

Filters before upload

Excluded apps and domains — and your private title-keyword rules — are applied on your Mac and dropped before anything leaves it.

Step 2 · FocusMirror server

Receives metadata only

App names, domains, time ranges, your typed goal. No titles, no content — the server cannot leak what it never receives.

Step 3 · Your dashboard

Yours alone

Single-user accounts, row-level secured. No team features, no admin views, no export an employer could request.

Commitments, code-mapped
No keylogging — ever

FocusMirror records which apps and sites you use, as time ranges. Never what you do inside them.

Enforced byThe upload schema is strict: exactly app name, bundle id, domain, time range, and a category hint. Unknown fields reject the whole batch — they are never silently stripped.

Titles never leave your device

Window titles are read on-device for exactly one purpose: applying your exclusion rules (including private title-keyword rules that exist only on your device). Then they're discarded.

Enforced byThere is no window-title column in the database and no field for it in the wire protocol. The guarantee is structural — the server cannot store what it cannot receive.

Never sold. Never shared. Never ad-trained.

Your activity is never sold to anyone, shared with third parties, or used to train advertising or anyone else's models. There is no data-broker business hiding behind the product.

Enforced byThe only third parties in the loop are infrastructure we pay (hosting, the AI model that writes your summaries) — bound by contract, never given raw events. AI sees time blocks only, and only if you opt in.

No employer access. No boss dashboard.

FocusMirror is a personal product. No team features, no admin roles, no organization accounts, and no export an employer could request from us.

Enforced bySingle-user rows protected by row-level security; an automated test proves a second account sees zero of your rows. Terms prohibit tracking machines you don't own or control.

Excluded means invisible

Mark any app or domain excluded and FocusMirror behaves as if it doesn't exist. Clinical software (Epic, Cerner, athena) and credential managers are excluded by default.

Enforced byFiltering runs in the app on your device before anything is uploaded, and an excluded stretch breaks the surrounding record so its time isn't attributed elsewhere.

AI never sees raw events

Models receive time blocks — categories, durations, app names, domains — plus the goal you typed. Most classification doesn't use AI at all: a shared catalog matches apps and domains directly.

Enforced byThe summarize jobs are fed from the time_blocks table only. The only strings any model ever sees from tracking are app names, domains, category labels, durations, and your own typed goal.

Tracking consent ≠ AI consent

You consent to tracking and to AI processing separately, before your first session. Decline AI and the dashboards still work — you just get no model-written summaries.

Enforced byConsent is recorded as append-only, versioned events; AI jobs check it before running.

Delete everything, anytime

Deleting a session permanently removes it and every insight derived from it. Old raw events also age out on their own: a rolling purge deletes them after 90 days (7 on Free) — trends only need the derived layers.

Enforced byHard deletes cascade through foreign keys in one transaction; every delete writes an auditable deletion record; an automated test requires zero orphans.

Everything is exportable

Take all of it with you as JSON whenever you want. No lock-in, no retention games.

Enforced byOne-click export ships at launch; same-day support request until then.

Verified by Apple

Why macOS says “verified developer.”

The FocusMirror app is signed with an Apple Developer ID and notarizedby Apple — Apple scans each release for malicious content before it ships. That's why, on first launch, macOS shows a verified-developer prompt rather than an "unidentified developer" warning. It's a check you can rely on for software distributed outside the App Store.

Signed & notarized · Apple Silicon · download details →

Security posture

The structural protections, stated plainly.

Account isolation

Every row is scoped to your account by row-level security. An automated test proves a second account sees zero of your data.

On-device filtering first

Excluded apps and domains are dropped on your Mac before upload — the server never receives them.

Server-side validation

The upload schema is strict and rejects any batch with unknown fields; the entitlement that gates features is computed server-side, never by the client.

Hard-delete cascade

Deletes remove every derived row in one transaction and write an auditable record. A test requires zero orphans.

No team or admin surface

There are no organization accounts, admin roles, or manager dashboards in the product at all.

Signed & notarized builds

The Mac app is signed with a Developer ID and notarized by Apple before each release.

Your controls

The levers are yours, not ours.

Exclude

Add any app or domain to your exclusion list and it's filtered on-device, before upload. Sensitive apps are excluded by default.

Pause & stop

Tracking only runs inside a session you started. Pause or stop and nothing is captured — the icon always shows the true state.

Delete

Delete any session, or your whole account, and every derived insight is hard-deleted in the same transaction. Gone, not hidden.

Export

Pull everything we hold about you as JSON, on demand. Your data is portable by default.

Fair questions

The ones people actually ask.

A formal Privacy Policy and Terms of Service — reviewed by a privacy attorney — publish with the launch. This page states what the software does; those documents will state your legal rights. If anything here ever conflicts with what the product does, that's a bug: report it and we'll fix the product, not the page.